2rinkan-api-2026 · Disclosed 2026-04-23
2りんかんイエローハット: unauthorized access and impact
The application API was abused to retrieve membership data; the specific authorization defect or vulnerability is undisclosed. Membership information for 3,179,454 people was leaked, revised from a maximum of 3,455,754. Separately managed payment data was excluded.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
The application API was abused to retrieve membership data; the specific authorization defect or vulnerability is undisclosed.
[s1]6月19日最終報 §§1-3 / 4月23日第一報 - Reported fact
Membership information for 3,179,454 people was leaked, revised from a maximum of 3,455,754. Separately managed payment data was excluded.
[s1]6月19日最終報 §§1-3 / 4月23日第一報
Timeline
Disclosure date established by the reviewed notice. [s1]
Reported response
- Reported fact
Individual notification is complete; the suspended application is being rebuilt. Logout and password reset are planned on reopening.
[s1]6月19日最終報 §§1-3 / 4月23日第一報
Evidence relevant to prevention
Insufficient evidence
Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The API abuse is established; the notice does not establish a specific IDOR or SQL injection flaw. Revised records replace the original estimate.
Sources
[s1] 2りんかんイエローハット · Primary source
2りんかんイエローハット:事故に関する公表資料 ↗Reviewed 2026-10-09